Impact
The LA‑Studio Element Kit for Elementor plugin contains an unauthenticated broken access control flaw in versions 1.6.2 and older. This weakness allows an attacker to bypass permission checks and perform privileged tasks such as altering plugin settings, manipulating website content, or viewing sensitive data, thereby compromising the confidentiality and integrity of the site. The vulnerability is classified as CWE‑862.
Affected Systems
WordPress sites that have the LA‑Studio Element Kit for Elementor plugin installed and active on any version 1.6.2 or earlier are affected. The vendor is LA‑Studio and the product is the Element Kit plugin for Elementor.
Risk and Exploitability
The CVSS base score of 5.3 indicates moderate severity. The EPSS value of less than 1 % indicates a low probability of exploitation in the near term, and the vulnerability is not listed in the CISA KEV catalog, implying no known public exploits. The likely attack vector, based on the description, is remote exploitation via unauthenticated HTTP requests to the plugin’s administrative or configuration endpoints that lack proper access control.
OpenCVE Enrichment